Effective Date: November 3, 2021
This Privacy Policy (“Policy”) describes the data collected (“Collected Data”) by or on behalf of thoughtfully.com (“we,” “us,” or “our”) and its vendors through this website or through other customer service channels, such as email and our customer call center (“Site”), and how Collected Data is used and shared. If you have questions or concerns about this Policy, please contact us at the contact information below.
By using the Site, you acknowledge on behalf of yourself and any organization that you represent (together, “you”) that you have read and understand this Policy. We may modify this Policy at any time. All changes will be effective immediately upon posting to the Site. Material changes will be conspicuously posted on the Site or otherwise communicated to you.
If you are a California resident, additional information applicable to California residents is below in the Section titled “Your California Privacy Rights.”
Personal Information. You can visit the Site without sharing personally identifiable information. However, you will be required to provide personally identifiable information in order to use certain features of the Site, for example, to complete an online purchase. If you want to open an account, your name, email and password are required.
Otherwise, you decide what personally identifiable information you want to share with us. We will collect whatever you voluntarily provide, such as your name, email address, postal/physical address, telephone number, birthday, and payment information, as well as any information about any gift recipient that you provide to us. If you elect to provide information that personally identifies you (“Personal Information”) such as your name, email, mailing address, or phone number, we will collect, use, and share it pursuant to this Policy and applicable law.
Telephone Numbers. If you provide your mobile or other telephone number to us, you consent to receiving telephone calls (both in-person and automated) from us at that telephone number. We will use your personally identifiable information as described below, including to process your orders for products and services, to communicate with you in connection with your orders, and to provide you with information and communications that you request or that we believe are relevant or may be of interest to you, subject to applicable laws and the terms of this Privacy Policy. You may elect to receive text messages from us. When you sign up to receive text messages, we will send you information about promotional offers and more. These messages may use information automatically collected based on your actions while on the Site and may prompt messaging such as cart reminders. If you opt in to have SMS notifications sent directly to your mobile phone, we receive and store the information you provide, including your telephone number or when you read a text message. You may opt out of receiving text messages at any time by texting “STOP” to our text messages. For more information about our text messaging terms, see our Terms of Use.
Payment Information. Purchases of products or services must be made by a credit card, debit card, or through PayPal. To make a purchase, you will need to submit your name and your credit or debit card type, number, expiration date, security code, and billing address. All credit and debit card information is provided directly to our PCI-compliant third-party payment processor. Thoughtfully does not directly access or handle your credit or debit card information. Payment by credit or debit card is subject to the approval of the card issuer. If you make a purchase using PayPal, you will need to log in to your PayPal account. PayPal's information practices are described in itsprivacy policy.
Mailing List Information. If you make a purchase from us or otherwise sign up or opt in to receive promotions from us, we will use the contact information you provide to send you promotional materials and electronic communications. We may use third-party email providers to deliver these communications to you. You may opt out of receiving promotional emails from us at any time by following the unsubscribe instructions contained in the applicable email (there is an Unsubscribe link located in the footer of all emails that we send). Opting out of marketing communications does not opt you out of transactional communications related to your orders.
Job Application Information. If you want to submit an application for employment with us, you will be redirected to our third-party provider that runs our recruiting website. This Privacy Policy does not govern their website, but please be advised that any information you share with such third-party website may be shared with us for purposes of your application.
User-Generated Content. We will collect any comments, reviews, blogs, images, data, text, and other content that you create, post, or otherwise submit via the Website (collectively, "User-Generated Content"). We may use your name in connection with any reviews or other feedback that you elect to provide. Any user communications will not be considered or treated as confidential.
Sweepstakes & Contests. We may offer sweepstakes or contests. To participate you must submit certain data, which may include your name, email, organization name and type, phone number, physical address, and other Personal Information. Data collected via sweepstakes and contests will be (i) used to contact you with promotional and related communications, (ii) shared with third-party vendors, and (iii) subject to additional terms provided to you at such time.
IP Addresses, Cookies, & Similar Tracking Technologies. When you use the Site, we and our Site vendors use technologies such as cookies (i.e., small pieces of data stored on your device's hard drive by your browser), web beacons, pixel tags, and similar technologies to automatically collect internet protocol addresses assigned to the computers and other devices you use, your internet service provider, device ID number, approximate geographic location, browser type, Site pages visited, websites you access before and after visiting the Site, and data related to how and when you use the Site (e.g., date and time stamps, clickstream data, and data about search terms and websites that direct you to the Site). We may combine this Collected Data with other Collected Data (including Personal Information) and data obtained from third parties.
The Site may use session, persistent, and flash cookies (local stored objects) to collect and store data about your preferences and navigation to, from, and on our Site. Session cookies are used to complete transactions and for other purposes such as counting visits to certain webpages. Session cookies are eliminated when you exit your browser. Persistent cookies may be stored on your computer by your browser. When you log in, persistent cookies tell us if you have visited the Site before or if you are a new visitor.
Flash cookies differ from browser cookies regarding the amount and types of data collected and how the data is stored. Cookie management tools provided by your browser will not remove and cannot manage Flash cookies. To learn about managing your Flash cookie settings, visit the Flash player settings page on Adobe's websitehere.
Most browsers automatically accept cookies. You can disable this function, but disabling cookies may impact your use and enjoyment of the Site.
Do Not Track Requests. DUE TO THE AUTOMATIC COLLECTION OF DATA USING COOKIES, WE DO NOT HONOR “DO NOT TRACK” REQUESTS.
Analytics. We may occasionally enable and implement various analytics tools, such as Google Analytics, which is an analytics tool provided by Google to collect and process Collected Data consisting of certain telematics about your use of the Site. Google sets and reads cookies to collect such Collected Data and your web browser will automatically send such Collected Data to Google. Google uses this data to provide us with reports that we use to improve the Site's structure and content.
We may occasionally enable and implement additional add-on services to Google Analytics, such as Demographics and Interest Reporting. Demographics and Interest Reporting uses cookies to collect data about our Site traffic by tracking users across websites and across time to provide us with analytics on our user base.
To learn more about how Google uses data, visit Google's Privacy Policy and Google's page on “How Google uses data when you use our partners' sites or apps.” You may download and install theGoogle Analytics Opt-out Browser Add-on for each web browser you use. Using the Google Analytics Opt-out Browser Add-on does not prevent the use of other analytics tools. To learn more about Google Analytics cookies, visitGoogle Analytics Cookie Usage on Sites.
Online Behavioral Advertising. We may occasionally use advertising networks and services provided by third-party vendors. These services collect data about your interactions with the Site and other websites across the internet and use such data to target personal content and advertisements for goods and services. The data collected may be associated with your Personal Information. The targeted content and advertisements may appear on the Site and on other websites and may be sent to you via email. Advertising networks often gather data about consumers who view advertisements to make inferences about a consumer's interests and preferences, which enables the delivery of advertisements directly targeted to the consumer’s specific interests. This practice is often referred to as “online behavioral advertising.”
For example, we may use Google Ads to serve ads on our behalf across the internet and on the Site. Google uses cookies and similar technologies to collect data about your visits to the Site and your interaction with our services to generate targeted advertisements to you on other websites that you visit across the internet. To opt out of remarketing advertising provided through Google, to customize your ad preferences, or to limit Google's collection or use of such data, visitGoogle's Safety Center andGoogle's Ad Settings and follow Google's personalized ad opt-out instructions. Opting out will not affect your use of the Site.
To change your preferences with respect to certain online ads and to obtain more information about third-party ad networks and online behavioral advertising, visit theNational Advertising Initiative Consumer opt-out page or theDigital Advertising Alliance Self-Regulatory Program. Changing your settings with individual browsers or ad networks will not necessarily carry over to other browsers or ad networks. As a result, depending on the opt-outs you request, you may occasionally still see our ads.
Social Media. We are active on social media, including Facebook, YouTube, Pinterest, Twitter, and Instagram (“Social Media”). You may comment on Social Media regarding Thoughtfully and our services.
The Site allows you to connect and share data with Social Media. These features may require us to use cookies, plug-ins, and APIs provided by such Social Media to facilitate those communications and features.
Anything you post on Social Media is public information and will not be treated confidentially. We may post (or re-post) on the Site and our Social Media pages any comments or content that you post on our Social Media pages. YOU AGREE TO HOLD THOUGHTFULLY AND ITS AFFILIATES HARMLESS AND WITHOUT LIABILITY FOR THE RESULTS OF ANY AND ALL CONTENT YOU POST ON THOUGHTFULLY'S SOCIAL MEDIA.
Your use of Social Media is governed by the privacy policies and terms of the third parties that own and operate those websites and not by this Policy. We encourage you to review those policies and terms.
The Site may use advertising networks and services offered by Social Media to deliver advertising content. Use of these services requires Social Media to implement cookies or pixel tags to deliver ads to you while you access the Site.
Video Content. The Site contains videos and embedded content made available by Thoughtfully, including visible content and/or feeds scripts embedded in the Site's code. Thoughtfully, along with the other parties that host this video content to stream on the Site, may collect data about how you interact with such content. Specifically, our use of YouTube content requires us to implement certain application programming interfaces (APIs) from YouTube, which allow for data collection, disclosure and use by YouTube pursuant to the Google Privacy Policy availablehere, whether or not you watch such videos. You may revoke YouTube's access to your data by visiting the Google security settings page availablehere.
Data from Other Sources. We obtain data about individuals from various third-party companies and public sources and we may combine that data with Collected Data. This enhances our existing data about our users and customers (e.g., adding address data) and improves our marketing efforts.
Beyond the uses and sharing described above, Thoughtfully and its vendors may use and share Collected Data (including Personal Information) as described below. We do not sell or rent Collected Data except as stated in this Policy and as permitted by applicable law.
Purpose Collected & Communication with You. We use and share Collected Data for the purpose for which it was collected. For example, if you contact us for support or assistance, we may use Collected Data to contact you and assist you with your request. We may use Collected Data to notify you of Site changes (e.g., changes to our Terms of Use or this Policy), and if you opt in, to send you marketing communications.
Affiliates, Vendors, & Other Partners. We may share Collected Data with our affiliates, third-party vendors, service providers, suppliers, consultants, agents, sales representatives, resellers, and other partners (including Site management and hosting, marketing and public relations, and email services) that provide data processing services to us (e.g., to support the delivery of, provide functionality on, or help to enhance the security of the Site) or otherwise process Collected Data for purposes described in this Policy or communicated to you when we collect such data (e.g. to send you emails, deliver orders, etc.). The parties described in this paragraph are authorized and may use and disclose Collected Data as needed to provide the applicable services to us and as provided by their own privacy policies.
Aggregated Data. We may use Collected Data to create anonymous aggregate data. We may use and share such aggregate data with our affiliates, vendors, and other third parties to: (1) analyze, develop, and improve the content and services that we make available, (2) inform business strategies, (3) understand the Site's demographics and user preferences, (4) customize promotional emails and users' Site experience, and (5) for other lawful purposes.
Security & Protection of Rights. We may use Collected Data and share it with third parties if we believe it is needed to operate the Site or to protect our rights or the rights of others, including sharing data needed to identify, contact, or bring legal action if our contracts, terms, or policies are violated or if required by law.
Business Transactions. All Collected Data is exclusively our property. If we undergo a change or contemplated change in control, acquisition, merger, reorganization, or asset sale, all Collected Data may be transferred, sold, shared, or otherwise shared with potential and actual successors, which will be bound by this Policy as it applies to Collected Data.
With Your Consent. With your consent, we may use or share Collected Data in ways not specifically described in this Policy.
Special Categories of Personal Information. “Special Data” is any data that reveals your racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, or that involves genetic or biometric data or data concerning health or sexual orientation. We do not intend to collect any Special Data from you. Please do not provide Special Data to us.
Children. We are committed to protecting children's privacy. The Site is not directed at children under 13 years of age. We do not knowingly collect, use, or share data from children under 13. If a parent or legal guardian learns their child provided us with Personal Information without his or her consent, please contact us.
We use commercially reasonable technical and organizational measures to help secure all Collected Data against loss, misuse, and alteration. While we cannot guarantee it, we use industry-standard protections to help safeguard against such occurrences. If a breach of our systems occurs, we will notify you of the breach only if and as required under applicable law.
YOU UNDERSTAND THAT NO DATA TRANSMISSION OVER THE INTERNET OR A MOBILE DEVICE CAN BE GUARANTEED TO BE 100% SECURE. WHILE WE STRIVE TO PROTECT YOUR PERSONAL INFORMATION, WE DO NOT GUARANTEE THE SECURITY OF PERSONAL INFORMATION AND YOU PROVIDE PERSONAL INFORMATION AT YOUR OWN RISK.
This Site is operated and maintained by Thoughtfully from the United States and is intended solely for a United States audience. If you access the Site from outside the United States, please be aware that Collected Data will be transferred to, stored in, and processed in the United States. U.S. data protection and related laws may not be as comprehensive as those from where you access the Site.
The Site may link to, or be linked to, websites not controlled by us. We are not responsible for third-parties' privacy policies or practices. This Policy does not apply to any third-party websites or to any data that you provide to third parties. You should read the privacy policy for each website that you visit.
To access or update your Personal Information as it exists in our records, please contact us using the information below.
If you have questions or concerns regarding this Policy,contact us
Subject to certain limitations, if you are a California resident you may make the following requests with regard to your Personal Information. Terms used below have the meaning given those terms under the California Consumer Privacy Act, as it may be revised from time to time (“CCPA”).
Non-discrimination. You have a right to exercise the below rights and we will not discriminate against you for exercising these rights.
Your Rights to Opt-Out of the Sale of Personal Information. California residents may direct us not to sell their Personal Information (this is your right to “opt-out”). You may submit your opt-out request here or you may otherwise contact us at set forth below. You may make a request to opt-out of the sale of your Personal Information on behalf of yourself or on behalf of a child if you are a parent or legal guardian of the child. An authorized agent may submit this request to opt-out of the sale of Personal Information only if you provide them with your signed permission to do so and, if the agent is a business, the agent is registered with the California Secretary of State. We may request a copy of your signed authorization and may deny your request to opt-out if we do not receive your signed authorization to the agent. We may also deny your request to opt-out of the sale as otherwise permitted by applicable law or regulation.
Based on current California law, to our knowledge we have not sold any Personal Information of an individual under 16 years of age.
Right to Know. You have a right to request access to the following information:
Right to Access. In addition, you have a right to request that we disclose to you the specific pieces of Personal Information that we have collected about you in the prior 12-month period.
Right to Deletion. You have a right to request that we delete Personal Information we collected from you.
How to Exercise Your Right to Know, Access and Deletion. To exercise your rights to request the above information or deletion, you may submit your request to us at any of the following:
Who May Exercise Your Right to Know, Access and Deletion. You may make a request to exercise the above rights to know, access and deletion on behalf of yourself or on behalf of a child if you are a parent or legal guardian of the child. In addition, you may authorize an agent to exercise these rights on your behalf, if you provide the agent with written permission and, if the agent is a business, the agent is registered with the California Secretary of State. If an authorized agent contacts us to exercise the above rights, we will need to verify their identity as well as your identity. We will also require proof of your written authorization to the agent both to act as your agent and to submit the particular request to us, unless the agent is subject to a Power of Attorney under California probate laws.
Verification of Your Request to Know, Access and Deletion. Once we receive your request, we will contact you to confirm receipt of your request. In addition, we may contact you to provide us with additional information to allow us to verify your identity based on the Personal Information we have in our systems. In order to verify your request, you must provide sufficient information that allows us to reasonably verify you are the person that is the subject of the Personal Information you have requested. This information may vary depending on the Personal Information we already have. Certain types of requests may require additional verification to ensure you are who you say you are. If you have used an agent to make your request, we will also need to verify the identity of the agent. Verification of your request may require you, or your agent if applicable, to sign a declaration under penalty of perjury verifying identity. We may deny your request as permitted by law, if we are unable to verify your identity, or if an agent makes the request on your behalf, if we are unable to verify their identity or proof of their authorization.
When We Will Respond to Your Request to Know, Access and Deletion. We will confirm receipt of your request within 10 business days. We will try to respond to your request within 45 calendar days. If we require additional time to respond, we will inform you of the reason and may take an additional 45 calendar days to respond. Any disclosures we provide will only cover the 12-month period preceding our receipt of your request. We may charge a fee to process or respond to your request if it is excessive, repetitive, or manifestly unfounded.
Based on the categories required by California law, below are the lists of Personal Information collected, where they are sourced, the purposes for which they are collected or sold, and to whom they are disclosed or sold.
Category of Personal Information | Source | Purpose Collected or Sold | Disclosed for a Business Purpose | Categories of Entities We Disclose To for Business Purposes | Sold | Categories of Entities We Sell To |
---|---|---|---|---|---|---|
Identifiers | Directly from you via our Site |
| Yes |
| Yes |
|
Personal Information categories under California Customer Records statute (Cal. Civ. Code 1798.80(e)) | Directly from you via our Site and other online services |
| Yes |
| Yes |
|
Commercial information | Directly from you via the transactions you conduct online |
| Yes |
| No | N/A |
Employment information | Indirectly from you via our third party job application tool when you submit a job application | Reviewing your job application and making hiring decisions | Yes | Service providers involved in the provision, maintenance and improvement of our Site and other online services | No | N/A |
Education information | Indirectly from you via our third party job application tool when you submit a job application | Reviewing your job application and making hiring decisions | Yes | Service providers involved in the provision, maintenance and improvement of our Site and other online services | No | N/A |
Internet |
|
| Yes |
| Yes |
|
Geolocation (approximate only) | Directly from you via IP address | Tracking use of our Site and other online services | Yes |
| No | N/A |
Inferences | Directly from you | Improving the services and products that we provide | Yes |
| No | N/A |
Although the categories of information above are collected for the designated purposes, Personal Information may be otherwise used for the purposes set forth in this Policy.